Related Experiment Videos
Explainable Feature-Group-Aware Cross-Attentive Expert Fusion for IoMT Intrusion Detection
Asmatullah Khan1, Yang Li1, Ijaz Khan2
1School of Information and Communication Engineering, Changchun University of Science and Technology, Changchun 130022, China.
None:
The Internet of Medical Things (IoMT) has become a core component of the modern healthcare system, but its increasing connectivity also exposes medical networks to diverse cyber threats. Although recent threat detection frameworks have demonstrated strong predictive performance, many still operate as black-box models. They offer limited or no interpretability of their decisions. This paper proposes an explainable hybrid IDS framework for multiclass IoMT intrusion detection. The proposed framework partitions network traffic features into semantically related groups and employs specialized expert networks to learn complementary traffic representations. A gate-balanced Mixture-of-Experts (MoE) routing mechanism adaptively aggregates expert outputs, while a cross-expert self-attention module captures contextual dependencies among expert representations. Furthermore, the proposed framework incorporates multi-level interpretability through SHAP, LIME, and expert-routing analysis to explain both feature contributions and internal decision behavior. We evaluate the proposed framework on two recent IoMT benchmarks, namely CICIoMT2024 and IoMT-TrafficData, under 6-class, 19-class, and 9-class multiclass settings, respectively. On CICIoMT2024, the proposed IDS achieves 99.76% accuracy and an MCC of 0.9951 in the 6-class setting, while attaining 99.07% accuracy and an MCC of 0.9892 in the 19-class setting. On IoMT-TrafficData, the proposed framework achieves 99.92% accuracy and an MCC of 0.9988 in the 9-class setting. The explainability results further show that the model identifies meaningful traffic features and exhibits class-dependent expert specialization, thereby improving transparency in its decisions. These findings confirm that the proposed framework provides an effective and interpretable solution for securing IoMT systems.